Sign inSign up

kubed/rclone

By kubed

•Updated 4 months ago

Image
0

527

kubed/rclone repository overview

⁠RClone

A nice way to copy stuff about and mount all kinds of drives — and the home of the kubed/rclone image, a standardized backup / restore tool other apps can drop in.

⁠Backup / Restore Image

kubed/rclone wraps rclone/rclone with gpg and two streamed scripts so any app can archive a directory to object storage and pull it back, encrypted, with no plaintext ever touching disk:

  • backup — tar the source dir → gpg encrypt → rclone rcat to the remote
  • restore — rclone cat → gpg decrypt → tar extract into a dir

Everything is piped; the only on-disk state is a throwaway GPG keyring in a tmp dir. The scripts don't care what's in the directory or how it got there — that's the calling app's job. They only do tar + gpg + rclone. The rclone.conf (the remote definition) is injected by the caller, never baked in.

Pick the mode with the first arg: backup or restore. Any other argument is passed straight through, so the image still works as a plain rclone CLI.

⁠Configuration
VarbackuprestoreDescription
REMOTE✓✓rclone remote + bucket, e.g. gcs:backups.example.com
SOURCE_DIR✓✓directory to archive / extract back into
PREFIXremote folder (default: basename of SOURCE_DIR)
RCLONE_FLAGSextra rclone flags (e.g. --gcs-bucket-policy-only)
GPG_RECIPIENT✓key id / email to encrypt to
GPG_PUBLIC_KEY✓armored public key, imported before encrypting
KEEPbackups to retain per prefix, 0 = all (default: 7)
GPG_PRIVATE_KEY✓armored private key, imported before decrypting
GPG_PASSPHRASE✓passphrase protecting the private key
RESTORE_DIRextract target (default: SOURCE_DIR)
FILENAMEspecific object to restore (default: latest)

Backups are named <UTC-timestamp>.tar.gz.gpg (e.g. 2026-06-10T22:11:13.tar.gz.gpg). The timestamp is zero-padded and big-endian, so a plain lexical sort == chronological — which is all "latest" and retention rely on. The PREFIX folder identifies the source, so the name needs no prefix.

⁠Example (Kubernetes)
containers:
- name: backup
  image: kubed/rclone:latest
  args: [backup]            # or: [restore]
  env:
  - name: REMOTE
    value: gcs:backups.kubed.io
  - name: SOURCE_DIR
    value: /data
  - name: RCLONE_FLAGS
    value: --gcs-bucket-policy-only
  # GPG_* + RCLONE_* creds injected from secrets
  volumeMounts:
  - { name: data, mountPath: /data }
  - { name: rclone-conf, mountPath: /config/rclone }

⁠Add the Alias.

alias rclone='op run --env-file="${CLUSTER_HOME}/apps/rclone/op.env" -- docker compose -f ${CLUSTER_HOME}/apps/rclone/docker-compose.yaml -p cluster run --rm --entrypoint rclone rclone'

⁠Mounting a Bucket

rclone mount gcs:backups.kubed.io /data/backups --allow-other --vfs-cache-mode full --cache-dir=/data/cache1

⁠List Contents of Bucket

rclone ls gcs:backups.kubed.io

⁠Syncing a folder to and from a bucket

rclone sync ./ gcs:backups.kubed.io --gcs-bucket-policy-only

from bucket to local dir

rclone sync gcs:backups.kubed.io ./ --gcs-bucket-policy-only

⁠Untar into Cur Dir

rclone cat gcs:backups.kubed.io/ldap/ldap.tar.gz.gpg

⁠Copy up archive

rclone copy ./ldap.tar.gz.gpg gcs:backups.kubed.io/ldap/ --gcs-bucket-policy-only

⁠Decrypt with cat

rclone cat gcs:backups.kubed.io/ldap/ldap.tar.gz.gpg | gpg --decrypt | tar xz -C ./data

⁠Delete a folder

rclone purge gcs:backups.kubed.io/ldap

⁠References:

Tag summary

Content type

Image

Digest

sha256:9481a4adc…

Size

38.8 MB

Last updated

4 months ago

docker pull kubed/rclone